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We report the security analysis of time-coding quantum key distribution protocols. The protocols 
make use of coherent single-photon pulses. The key is encoded in the photon time-detection. The use 
of coherent superposition of states allows to detect eavesdropping of the key. We give a mathematical 
model of a first protocol from which we derive a second, simpler, protocol. We derive the security 
analysis of both protocols and find that the secure rates can be similar to those obtained with the 
BB84 protocol. We then calculate the secure distance for those protocols over standard fibre links. 
When using low-noise superconducting single photon detectors, secure distances over 200 km can 
be foreseen. Finally, we analyse the consequences of photon-number splitting attacks when faint 
pulses are used instead of single photon pulses. A decoy states technique can be used to prevent 
such attacks. 



o : 

wo: 
s . 

<: 
m : 



^ ■ 

or 
i 

^— > ■ 
c ■ 

ctf ■ 
=5 

cr 



> 
cn 
oo 

oo 
o 



I. INTRODUCTION 

Quantum key distribution (QKD) exploits the fundamental principles of quantum mechanics to securely distribute 
a cryptographic key between two parties usually called Alice and Bob. The purpose of QKD is not to prevent a 
third party Eve from eavesdropping the line, but to make eavesdropping systematically detectable by Alice and Bob. 
According to their information advantage over Eve, Alice and Bob can distill a secret key. Quantum key distribution 
has been widely developed in recent years 0, HJ. The proposed protocols are based on photon-counting 0-0] or 
continuous variable as well @-[l(|. An important effort has been devoted to the realization of practical and reliable 
prototypes that has culminated recently with the demonstration of fully integrated held demonstrations of 

QKD networks within the framework of the SECOQC project [16|,|l7| and of the UQCC 2010 conference [18| |. 

In view of practical applications we have proposed a simple protocol based on time coding that makes use of coherent 
single photon pulses with square profile and duration T [13, [2fJ . The key is encoded in the photon time-detection. The 
use of coherent superposition of states keeps Eve from eavesdropping the key without being noticed. This technique is 
attractive because it is one-way and it allows a simple implementation based on state-of-the-art optical components. 
A typical implementation has been proposed in [l9[ and is depicted on figure ([T]). We have considered several protocols 
based on such a principle. In the first one, depicted on figure ([2]), we have considered three time-slots 1, 2 and 3 of 
duration T/2 pf. We call this protocol Three Time-Slots protocol (3TS). 

Alice sends, at random and with equal probabilities, two kinds of pulses, encoding the bits and 1. Bit spans 
time-slots 1 and 2, bit 1 spans time-slots 2 and 3. Due to the non-orthogonality of the states encoding bit and bit 
1, it is impossible for the eavesdropper to preserve the coherence without introducing errors in the raw key. 

Other protocols have been proposed based on related principles. The Difierential-Phase-Shift (DPS) protocol sends 
temporal sequences of coherent pulses and encodes the key in the phase relation between successive pulses [2l| . The 
Coherent-One- Way (COW) protocol dHHU encodes the bits on pairs of adjacent time slots. In addition, it introduces 
superpositions of states spanning two time-slots. The COW protocol takes into account coherences between successive 
pulses, whereas in our protocol, we have considered internal coherences of the pulses. The exploitation of inter-pulses 
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Figure 1: Typical scheme of the experiment. Bob measures at random the time-detection of the photon or the coherence of the 
pulse. Here, a beamsplitter sends the pulses either to a photon-counter or to a Mach-Zehnder interferometer. 
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Figure 2: Principle of the Three Time-Slots protocol. Alice sends pulses of duration T with chosen delay or T/2. Bob measures 
the photon detection time. The time slots 1 and 3 are non ambiguous and allow for delay determination. The detections in 
time slot 2 are ambiguous and force Eve to introduce errors. 



coherence aims at protecting against Photon-Number-Splitting (PNS) attacks 123. 12311 . A complete proof of security 
is still to be performed on the COW protocol, although progress has been made [24j ]. 

In [TjJ, we had seen that it was possible to eavesdrop the channel as soon as its losses exceed 50 %. By doing this, 
Eve modifies the channel transmission for each time-slot and suppresses all the detection events corresponding to an 
ambiguous result (time-slot 2 in figure ©). To remedy this drawback we had proposed a four states protocol where 
the two additional pulses carry no information and where successive pulses have a T/2 overl ap [1 91 ] (figure [3]). Recent 
related proposals also make use of additional states to make the B92 robust against losses [25|]. It is in fact possible 
to keep the previous protocol with only three time-slots, if additional pulses of duration T/2 are combined at random 
with the pulses representing the bits. Measuring the number of such pulses received for each time-slot allows Alice 
and Bob to monitor the channel transmission for each time-slot and to ensure that it is not modified by Eve, which 
prevents attacks such as the previous one. 

In our previous works, we had considered only the simple case of intercept-resend attacks [l9l [20|. Our purpose is 
to generalize the study to optimal collective attacks where we consider the most general unitary transform allowed 
by quantum mechanics in order to upper bound the information that Eve can get on the key shared between Alice 
and Bob. The security of the key can be guaranteed when the mutual information between Alice and Bob Iab is 
greater than the mutual Holevo quantity between Alice and Eve xae [HI, [27| . In the present paper, we will first 
model the 3TS protocol where single-photon pulses spanning the time-slots (1,2) and (2,3) represent the bits and 1 
respectively. From the quantum model describing this protocol, we deduce a simplification that allows to consider a 
simpler protocol. The bits are then encoded on two adjacent but non overlapping pulses (time-slots 1 and 2). Pulses 
spanning time-slots 1 and 2 are combined at random with the previous pulses. They allow to check that the coherence 
is not affected by eavesdropping. We call this protocol the Two Time-Slots Protocol (2TS) as depicted in figure ((H). It 
has many similarities with BB84, and similar protocols have already been proposed 28, 29]. The states corresponding 
to the H-V basis is represented by the time-slots 1 and 2. Only one state of the non-orthogonal basis is used which 
is the pulse spanning time slots 1 and 2. We model Eve's attack introducing the most general unitary transform that 
could allow her to extract some information on the key. We perform the complete analysis of this protocol taking 
into account the imperfections of the system. We thus calculate the Holevo quantity between Alice and Eve, and the 
Shannon information between Alice and Bob as a function of the quantum bit error rate (QBER) for several values of 
the interferometer visibility. When the visibility of the interferometer is perfect, the expression of the Holevo quantity 
between Alice and Eve is identical to that obtained in the case of the BB84 protocol. The 2TS protocol can thus be 
viewed as a time-coding version of the BB84 protocol. 

The security analysis of the 2TS protocol is then used as an intermediate step to analyse the security of the 3TS 
protocol. Although less performant than the 2TS protocol, this protocol is secure up to a QBER of 5%. The main 
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Figure 3: Principle of the four states protocol. Alice sends pulses of duration T with chosen delays 0, T/2, T or 3T/2. Pulses 
(a) and (d) carry no information. Pulses (b) and (c) encode bit and bit 1 respectively. Bob measures the photon detection 
time. He keeps only the results corresponding to time slot 3 and time slot 5. The results are ambiguous, which prevents Eve 
from exploiting the losses of the line. 
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Figure 4: Principle of the Two Time-Slots protocol. Alice encodes the bits in successive non-overlapping single-photon pulses 
with duration T/2 (solid line). In addition, she sends at random single-photon pulses spanning the time-slots 1 and 2 allowing 
a coherence measurement aiming at detecting eavesdropping (dashed line). 



advantage of the 3TS protocol is that the pulses containing the information are similar up to a time shift. Whereas 
the 2TS protocol uses pulses of different length. This is an advantage in simplicity at the price of a reduction of 
the security. The 3TS protocol can be improved if the pulses carrying the bits are completed with additional pulses 
featuring a coherent superposition between time-slots 1 and 3. We call this improved version Completed Three 
Time-Slots protocol (C3TS). It is depicted on figure ([5]). The results are then the same as for the 2TS protocol. 

After having considered single-photon pulses in the previous cases, we then consider the case where Alice sends 
faint pulses instead of single-photons. In that case, the protocols are sensitive to photon number splitting attacks 
(PNS) where Eve keeps only the pulses where more than one photon is present, which allows her to get a perfect 
copy of the key. A counter-measure to such attack consists in introducing decoy states where the average value of 
the photon number in the pulses can take several values according to a given proportion [3fjl - l32j |. This keeps Eve 
from chan ging the number of photons in the pulses without being noticed. Using an approach closely related to that 
of [HI, [3lT l33l. HH , we calculate the rate as a function of the distance and compare it to that obtained in the case 
of single-photon pulses. As expected, we obtain a linear dependence with the channel attenuation in the case of 
single-photon pulses or decoy states, whereas it is quadratic without the use of decoy states. 
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Figure 5: Principle of the Completed Three Time-Slots protocol. Alice encodes the bits in overlapping single-photon pulses 
spanning the time-slots 1-2 and 2-3 respectively (solid line). In addition, she sends at random single- photon pulses spanning 
the time-slots 1 and 3 allowing a coherence measurement aiming at detecting eavesdropping (dashed line). 



II. QUANTUM FORMALISM 



The protocols introduced in the previous part can be modeled using a quantum formalism for the time-slots used 
to describe the pulses. Although the time scale of Bob can be divided in an infinity of time-slots, a natural limit is 
given by the period between two successive pulses. This period is divided in successive time-slots of duration T/2 
numbered from 1 to N, which gives rise toaiV dimensions Hilbert space. To each time-slot corresponds a basis state 
K)b («=1 to N) in Bob's Hilbert space. 

We start with the 3TS protocol, where Bob's Hilbert space is three-dimensional with basis states noted \2)b 
et |3)fl. The pulses chosen by Alice to encode the bits are represented by the states |/3i) and \^2). Since they have 
an overlap, they correspond to non-orthogonal states in Bob's space : 



|/3i> = ^(|1) B + |2)b) 
|/3 2 ) = ^(|2)b + |3) b ) 



(1) 
(2) 



Here we consider that Alice sends perfect pulses with no component of |/3i) on |3)b, and no component of on 
|l)s. The pulses are sent at random by Alice with identical probabilities equal to |. The state received by Bob is a 
statistical mixture given by : 



PB = \\Px){Pl\ + \\fa)iM 



(3) 



This description corresponds to the "prepare and measure" description of the protocol. It describes the practical 
way of preparing the pulses and sending them to Bob. An equivalent approach is called the "virtual entanglement" 
description [H, |3^|. Since there is no eavesdropping at this stage, Alice and Bob are isolated. We can introduce a 
Hilbert space for Alice and describe the whole system by a pure state in the joint Hilbert space of Alice and Bob. 
Alice's Hilbert space is described by a two orthogonal states basis \\)a and \2)a- These states can be associated with 
the bit and the bit 1 respectively. Before sifting, the state describing the system is : 
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%1) A \P 1 ) + %2) A \P2)\®\V) 1 



(4) 



The tensor product with the state \Q)e indicates that Eve does not interact with Alice and Bob. The partial trace of 
ab|V'i)(V'i|ab over Alice results in the density matrix ps- |V'i)ab is thus a purification of ps- 

Eq. allows a detailed description of the protocol. We first evaluate the visibility of the interferometer, which 
allows to check the coherence of the pulses received by Bob. According to fig. (JIJ, the photons detected at the output 
of the interferometer do not participate to the final secret key. Therefore, Bob can inform Alice when he has detected 
such a photon, and Alice can reveal which kind of pulse she has sent. For example, we consider that Alice has sent 
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a state |/3i). An additional two dimensional Hilbert space is introduced in order to describe the two arms of the 

interferometer with basis states \+}i and |— )/■ The incoming state is thus \in)i = ^{\1) B + |2)_b)|+)j- After the 
first beamsplitter, the system is described with a superposition of the two interferometer states. Then, the state of 
one arm experiences the transform \i) B — > \i + l)s in order to take into account the T/2 time difference between the 
two arms. Finally, introducing a possible phase-shift between the two arms, one ends up with the expression of the 
state at the output of the interferometer : 

lout): = ^ [(|1) B + (1 + e*)\2) B + e*»\3) B ) |+)x + (|1) B + (l - e*) \2) B - e*|3) B ) (5) 

From such an expression, it appears that, knowing that Alice has sent a state |/3i), Bob needs to keep only the 
detection events in time-slot 2 in order to measure the coherence of the pulse. In that case, a visibility of 1 is 
expected if no eavesdropping occurs. If a state is incoming, a similar expression will be obtained with all the 
states \i)b replaced with \i + 1) B in Eq. ([5]). Thus, a visibility of 1 can be obtained when keeping only the detection 
events in time-slot 3. Bob informs Alice each time he has detected a photon in time-slots 2 or 3 at the output of 
the interferometer. Alice then reveals whether she has sent a state or a state |/?2). Bob can then calculate the 
visibility of the interferometer which is equal to 1 in case no eavesdropping occurs. 

The state \ip\) ab can be equivalently written in Bob's basis : 

\i>i)AB = Q|1)a|1)b + \(\1)a + \2)a)\2) b + i|2) A |3> fl ) ® \0)e (6) 

Using Eq. (jj), one obtains that the time slots with non zero probability detection are 1 and 3 (probability 1/4) 
and 2 (probability 1/2). When detecting the pulses sent by Alice, Bob ensures that these probability detections are 
respected. The ket \2) B is correlated to a superposition of \1)a and 12)^, with equal weight. This state is thus 
ambiguous in the sense that it is impossible for Bob to know if Alice has sent a bit or a bit 1. The projection of 
\iPi)ab to the subspace (|1)b,|3)b) is given by 

\i>i-s)AB = [^\1)a\1)b + ^\2) A \3) B j ® \0)e (7) 

This state is maximally entangled between Alice and Bob. It denotes a complete correlation between the bit chosen 
by Alice and the detection in Bob's non-ambiguous time-slots 1 and 3. 

The expression of \tpi) ab given by Eq. ^ can be interpreted as a new protocol where Bob sends at random the 
states |1)a, \2)a or ^ A ^1 2 ^ A with respective probabilities of 1/4, 1/4 and 1/2. \1)a and \2)a are used to encode the 

key. The state Wa ^ )a is used to ensure that the eavesdropper does not break the coherence between 1 1) a and \2)a- 
It imposes a constraint on eavesdropping which ensures the security of the protocol. After the pulses have been sent, 
sifting occurs, and Bob informs Alice when he has sent states ^ A ^^ A . To establish the key, Alice and Bob keep 

only the states corresponding to Bob sending either \1)a or \2)a- The state representing the system after sifting is 
given by Eq. ([7]). Eq. © thus describes a protocol dual from that described by Eq. Finally, since Eq. (J7]) is 
symmetrical, the roles of Alice and Bob can be interchanged and one can assume that Alice sends the pulses and Bob 
detects the photons. We then have two protocols where Alice sends the pulses and Bob detects the photons. The 
one described by Eq. (j4]) uses a three-dimensional Hilbert space for Bob and corresponds to the 3TS protocol. It is 
the initially proposed time-coding protocol. The second protocol described by Eq. ^ uses only a two-dimensional 
Hilbert space for Bob and corresponds to the 2TS protocol. The security analysis of this latter is simpler and we will 
first analyse it. We will then use the main lines of the security analysis of the 2TS protocol to analyse the security of 
the 3TS protocol. 

III. SECURITY ANALYSIS OF THE TWO TIME-SLOTS PROTOCOL 

The state describing the joint Hilbert space of Alice and Bob, when the pulses are sent by Alice and no eavesdropping 
occurs, can be written : 

\^)ab = (\\1)b\1)a + \(\1)b + \2)b)\2>)a + ||2> b |2>a) ® |0) £ (8) 
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As compared to Eq. ©, we have reversed the roles of Alice and Bob and we have interchanged the kets \2)a and \3) A 
to have more symmetrical notations. Thus \1)a an d \2)a describe the pulses carrying the bits and \S) A describes the 
pulses carrying the coherence information. 

We then consider the general attack allowing Eve to be entangled with the states sent by Alice to Bob [l], H3, [H| . 
The two states of Bob are transformed according to the following relations. 

|1}b|0) e -> \1) E = y/*\\ll) \1) B + y/Ql\12) \2) B (9) 
\2)b\0)e ->■ \2) E = V^\22) \2) B + y/Ch\21) \1) B (10) 

In this transform, Eve's Hilbert space is described by the states where i and j refer to the initial state and 
to the final state of Bob, respectively. The normalisation condition implies F\ + Q\ = F2 + Q2 = 1. We consider 
that the attack of Eve can be asymmetric in the case where F± ^ Anyhow, we will show in the following that 
the symmetric attack is optimal. The joint Hilbert space of Alice, Bob and Eve is a closed system. Therefore, the 
transform must be unitary, which implies the relation : 

b(1|2) b = v/FiQ 2 (ll|21) + v/fKh(22|12) = 0; (11) 
The state resulting from Eve's attack is given by : 

Wiabe = ^|1>*|1>a + + \2)e)\3)a + \\2)e\2)a (12) 

Classical communication allows Alice to inform Bob whether she has sent a state carrying the bit information (subspace 
(ll^t),^))) or a state carrying the coherence information (subspace (|3^))). In order to consider the states carrying 
the bit information, Bob projects the state \iP)abe on the subspace (IIa),^)) given by : 

V2 r~ 1— 1— 1— 

\rpi-2)ABE = -y [y/F\\ll)\l) A \l)B + V / ^|22)|2) A |2 B ) + ^\12)\1) a \2)b + y/Ch\21)\2) A \l) B ] (13) 

The state described by Eq. (| 13[) is an entangled pure state between Alice and Bob on one hand and Eve on the other 
hand. The entanglement witnesses the correlations between Eve's measurement and Alice and Bob's measurement. 
The corresponding information can be quantified by the entropy of entanglement [3Qj | . Maximizing this quantity, 
Eve maximizes the knowledge she has on the key. From the state \1p1-2) abe, one can deduce the density matrix 
of the complete system p\-2^ BE = \1pi-2) ABE Abe (4>i-2\- The density matrix of the reduced system is defined by 
Pab = t?E(pi-2 ABE ) for Alice and Bob and pe = ^ab{pi-2 abe ) for Eve. The entropy of entanglement is defined by 



Sent = S(pAB) = S(p E ) (14) 

where S(p) = — tr(plog 2 (p)) is the Von Neuman entropy of p. In order to maximize her information, Eve has to 
maximize S(pab)- 

Pab is a 4 x 4 matrix in the basis (\1) a \1)b, \2)a\2)b, \1)a\2)b, |2)a|1)b). |1)a|1)b and |2) A |2) B form a basis for 
the subspace corresponding to Alice and Bob getting identical results. |1)a|2)b and |2)a|1)b) form a basis for the 
subspace corresponding to Alice and Bob getting different results. 

Let us apply the projective measurement on those two subspaces to pab ■ The resulting density matrix p' AB is given 
by: 



F t 



Pab 



V7\7M22|11) 





v / M(ll|22) 
F 2 








Qi 



VQlQ^(2i\i2) 



Q2 



As a result of a projective measurement, we have 



S(p'ab) > S{pab) 



(15) 



(16) 



S(pab) is maximized when pab is chosen identical to p'ab- This results from the loss of information when the non- 
diagonal blocks are taken equal to zero in pab- Each term of the non-diagonal blocks of pab depends only on one of 
the following scalar products : (11 j 12) , (11|21), (22 1 12) and (22 1 21) . Therefore, an optimal choice for Eve in order to 
maximize her information on the system is to choose those four scalar products equal to zero. 
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As a result, the unitarity condition Eq. (jlip is automatically fulfilled. In addition, the expressions of \1)e and \2)e 
are Schmidt decompositions for which Eve and Bob are maximally entangled. The attack performed by Eve introduces 
some errors. Since (11 1 12) = and (22|21) = the corresponding noise is incoherent and cannot be distinguished 
from any real noise coming from the imperfections of the experiment. 

The choice of the scalar products above is a first step for Eve to maximize her information on Alice and Bob's 
system. A further step would be to choose the two remaining scalar products equal to zero as well. Anyhow, the 
states of Eve would all be orthogonal one with another, and this would result in the impossibility to measure any 
interference at Bob's interferometer, which is a prerequisite for the protocol to be useful. Thus (1 1 1 22) and (12|21) 
are left as free parameters the value of which can be optimized by Eve. 

According to Eq. (JT¥J) and considering the optimal choice pab = p'ab^ & (pe) can be calculated from the eigenvalues 
of Eq. HU) using the definition S (p E ) = £* =1 -7ilog 2 (7i)- Defining F = \{F X + F 2 ), Q = \{Q X + Q 2 ) and 
dQ = o(Qi — Q2), the expressions of the eigenvalues are : 



7i 



\(f+ y(l-(ll|22) 2 )dQ 2 + (ll|22) 2 ^ (17) 



1 



72 = § I F - \l ( 1 - (11|22> 2 ) dQ 2 + (11|22) 2 ^ ] , IS) 



13 = 1 ( g + \/(l-(12|21) 2 )dg 2 + (12|21) 2 Q2 j rL!)) 



74 = i - y(l-(12|21) 2 )dQ 2 + (12|21) 2 Q^ ( 20 ) 

where ~~\ < dQ < \ and \dQ\ < Q < 1 — \dQ\. Studying the variations of S (pe) with dQ shows that it is maximal 
when dQ — 0, due to dependence of S (p E ) with the square of dQ. Therefore, Eve can maximize her entanglement 
with Alice and Bob choosing Fx = F 2 = F and Q\ = Q 2 — Q- 

The information available for Eve is upper bounded by the Holevo quantity defined by : 



X 



= S( Pe )~Y,P* S (Pe) (21) 



In the case where xae is calculated, the matrix p E is the density matrix of Eve when one knows which state has been 
sent by Alice. From Eq. (IT21) . those two states are \1}e and \2)e and one gets : 

1 (Fx \ 2 (Q 2 \ 



.0 Qx J ' HE ~ V F 2 
Since those states are equiprobable,we have Pi = p 2 = h , and the Holevo quantity becomes 



Xae = S (p E ) - \h{Qx) - \h(Q 2 ) (23) 

where h(Q) = -Qlog 2 (Q) - (1 - Q)log 2 (l - Q). 
The available secret bit per sifted pulse is given by 

AI = I AB - xae (24) 

Iab is the mutual information between Alice and Bob. In order to compute Iab, we have to take into account that 
the error rates are different, depending on which state 11)^ or |2),i is sent by Alice. Alice and Bob can measure 
those two errors rates revealing a fraction of the pulses that are sent. Since those pulses are equiprobable, the mutal 
information is the average of the mutual information corresponding to each state, and we obtain : 

Iab = 1 - \ iKQx) + KQ 2 )) (25) 
Combining Eq. (|2"3"|) and Eq. (|2"5|) . we obtain the expression of the secret key rate : 



AI=l-S{p E ) 



(26) 
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This expression shows that the secret bit rate is directly related to the entropy of entanglement. The goal of Eve is 
to minimize the secret bit rate and thus to maximize S(pe)- According to the previous derivation, we obtain that 
this occurs when dQ = 0, thus showing that the symmetric attack is optimal. In the following of the paper, we will 
thus consider that Eve's attacks are symmetric. 

In the next step, we optimize S (pe) for a given value of the fringe visibility measured at Bob's interferometer Vi 2 , 
which is measured when Alice sends a superposition state of the form -^=(\1) B + \2)b), and Bob takes into account 
the photons detected in time-slot 2. Due to Eve's action, V12 can be smaller than 1. Its expression is given by : 

Vi 2 = F(22|ll) + Q(12|21) (27) 

We find that S (pe) is maximum when (12|21) = (11|22) = V12. S max (pe) is thus given by: 

4 

Smax (pe) = V -A< log 2 (A,) (28) 



Ai = 




+ V12) 


A 2 = 




-Via) 


A3 - 




+ Vi 2 ) 


A 4 = 




-Vi 2 ) 



1=1 

with : 

(29) 
(30) 
(31) 
(32) 

We can then model the imperfections of the real channel between Alice and Bob. Alice sends a state represented by 
a density matrix pa- The channel is characterized by a global transmission 77. Assuming that the channel is symmetric 
and that the induced modification is independent from the initial state, we obtain a resulting state at Bob that has 
the following expression. 

Pb = VPA + : ^-^ / 2 (33) 

Where I2 is the 2x2 identity matrix. In case where the initial state is \1)b or \2)b, one obtains that the fidelity is 
^(1 + 77) and that the error rate is |(1 — if). In case where the initial state is a partially coherent superposition of 
states characterized by a visibility Va, the resulting visibility at Bob is Vb = t)Va- The lack of visibility at Bob occurs 
from two origins. The first one, represented by Va, is due to the intrinsic imperfections of the apparatus or a possible 
lack of coherence of the source. The second one, represented by 77, is due to the imperfect transmission channel. 

Eve substitutes her perfect measurement apparatus, represented by the unitary transform (Eq. Q and Eq. (JTUJ)) , 
to the imperfect channel between Alice and Bob. This is equivalent to a channel with transmission 77 = F — Q. The 
visibility measured at Bob is thus Vb — {F — Q)Va- It is assumed that Eve exploits all imperfections of the set-up, 
and thus she can set V12 = V B — (F — Q)Va- The values involved in S (pe) can be expressed by : 

(34) 
(35) 
(36) 
(37) 

From those expressions, we can compute the information curves represented on figure © for several values of Va 
as a function of Q. In the particular case of a perfect interferometer (Va — 1), the expression of xae simplifies to 
Xae 1 — h(Q), and the secret key rate becomes 1 — 2h(Q). It coincides with the bound given by GLLP [33| for the 
BB84 protocol when Eve launches a basis independent attack, with a maximum QBER of 0.11. 
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Mutual information (bit/pulse) 




Figure 6: Mutual informations as a function of the quantum bit error rate Q. The curves represent the Holevo quantity between 
Alice and Eve for visibilities Va equal to 0.9, 0.95 and 1. The solid lines represent Eve's information in the case of the Two 
Time-Slots protocol or the Completed Three Time-Slots protocol. For a visibility of 1, it crosses the curve representing the 
Shannon information between Alice and Bob, Iab, for a quantum bit error rate of 0.11. The dashed lines represent Eve's 
information in the case of the original Three Time-Slots protocol for the same values of the visibility. This procotol is less 
performant than the previous ones as shown for the maximal QBER and the available information per pulse that are smaller. 
Anyhow, security is still possible up to values of QBER equal to 5% when Va = 1. 



IV. SECURITY ANALYSIS OF THE THREE TIME-SLOTS PROTOCOL 



After analyzing the security of the two time-slots protocol (2TS), we can go back to the original three time-slots 
protocol (3TS). The state describing the whole system, when no eavesdropping occurs, is given by Eq. (fj|. The state 
corresponding to the projection on the basis states \1}b and |3)b is given by Eq. (0. The key is built upon those two 
states, and therefore, the attack of Eve should involve only them and not the state |2) b which does not play any role 
after sifting. As a consequence, the unitary transform describing the attack of Eve is similar to that used in the case 
of the 2TS protocol (Eq. © and Eq. (fTP]) ). the role of \2)b being played by |3}b- The state \2)b is transformed in 
a way similar to that of |1)b and |3)s. A fourth state |4)s is introduced to preserve the unitarity of the transform 
but it does not play any role in the security evaluation. Doing this, we find the same fidelity for all three states after 
Eve's attack. The unitary transform applied by Eve thus writes : 

|1)b|0)b->|1) b = \fi?\\l)\L) B + y/Q\M)\S)B (38) 
\2)b\0)e -> \2)e = \/F|22)|2) B + VQ|24)|4) S (39) 
|3> b |0)b -> |3) E = VF\33) \3) b + VQ\31) I l)u (40) 

In the case of the 2TS protocol, the security relies on a coherence measurement corresponding to Alice sending a 
superposition state -^=(|1) B + \2)g)- Similarly, in this case, Alice should send a superposition state -^=(|1) B + \3)b) 
between the two states involved in the key establishment. Then Bob should measure the coherence between those 
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two states after transmission through the channel, in order to evaluate the security of the exchange. In that case, one 
would expect to derive the same security analysis and to obtain exactly the same results as derived in part HID In 
particular, the information of Eve is maximized when the relation (13|31) = (1 1 1 33) = V13 is fulfilled. As compared to 
the original 3TS protocol, this implies for Alice to send additional superpositions of pulses spanning time-slots 1 and 
3 and for Bob to measure their coherence with an interferometer having a time propagation difference of T between 
the two arms. We will denote this protocol Completed Three Time-Slots protocol (C3TS). 

Similarly to the C3TS protocol, the original 3TS protocol makes use of \\)b and |3)b to carry the information. 
Therefore, the security analysis of the 3TS protocol is the same as that of the 2TS and C3TS protocols up to the 
expressions of the eigenvalues of S(pe) as a function of the visibility (Eq. (j2T))) to Eq. (1321) ). The difference between 
the 3TS protocol and the C3TS protocol lies in the way the visibility is measured in both cases. In the C3TS protocol, 
the visibility is measured between time-slots 1 and 3. In the original 3TS protocol, the interferometer measures the 
coherence between time-slots 1 and 2 and between time slots 2 and 3 respectively, as described in section [TTJ If Bob 
receives a superposition of states \1)b and \2}b he keeps only the photons detected in time-slot 2. If he receives a 
superposition of states \2}b and |3)b he keeps only the photons detected in time-slot 3. Therefore he can measure a 
visibility of 1 if no eavesdropping occurs. Taking into account Eq. (j38|) to Eq. (|40|. we can then calculate the visibility 
in case eavesdropping occurs, and we get : 

Via = (H|22) (41) 
V 23 = (22|33) (42) 

We can then relate the parameters F and Q to the parameters of the imperfect channel 77 and Va as we did in 
section ITO1 for the 2TS protocol. Since the key is established using a two states Hilbert space (|l)s, |3)s), we can 
derive the relations F — ^(1 + rf) and Q = ^(1 — 77) as we did previously, using Eq. (|33[) . Similarly, the visibility 
evaluation involves two dimension Hilbert spaces, either (|l)s, \2)b) or (\2)b, |3)b)- We then get similar values for 
the visibilities measured at Bob : V12 = V23 = t]Va- Finally, we get the relation : 

(11|22) = (22|33) = (F — Q)V A = cos{lp) (43) 

Similarly to the case of the C3TS protocol, Eve should optimize the angle between states |11) and 1 33} in order to 
minimize the scalar product (11 133) and thus maximise her information. The states |11), 1 22) and 1 33) form a three 
dimension space. The scalar product (1 1 1 33) is thus constrained by the previous relation since |11) and 1 33) both 
make an angle tp with 1 22) . As long as <p < the minimal value of the coherence between time-slots 1 and 3 is thus 
obtained when |11), 1 22) and 1 33) are in the same plane, and its value is given by 

Vi 3 = <H|33> = cos(2^) (44) 

A simple trigonometric expansion shows that (F — Q)Va should be replaced by 2(F — Q) 2 Vj — 1 in Eq. to 
Eq. (|57)l . The eigenvalues used to calculate the secure key rate become : 

Ai - Q{F-Q) 2 Vl (45) 

A 2 = Q(l — (F — QfVl) (46) 

A 3 - F(F-Q) 2 Vl (47) 

A 4 = F(l - (F - QfVl) (48) 

If <P > f i 1 11) and 1 33) can be chosen orthogonal, and Eve has a complete information on the key. 

This protocol is less performant than the 2TS protocol or the C3TS protocol (figure ©). In particular, Eve can 
obtain a complete information on the key as soon as 2(F — Q) 2 V\ — 1 = 0, which corresponds to Q — 0.15 in the case 
where Va = 1 • For the two other protocols, this occurs when Q = 0.5 independently of the value of Va- In the case 
of a perfect visibility (Va = 1), the maximum QBER is 5%, whereas it is 11% in the case of the 2TS protocol or the 
C3TS protocol. 



V. EVALUATION OF THE SECURE DISTANCE 



One of the main characteristics of a quantum key distribution link is its secure distance, i.e. the distance over which 
the mutual information Iab stays greater than xae [26| . Our security evaluation involves two parameters which are 
the fringe visibility Va and the QBER Q. In order to eavesdrop the key, Eve replaces the imperfect channel with 
transmission 77 with a perfect one having a transmission equal to 1. We assume in addition that Eve can control all 
the errors of the set-up. She can thus perform an attack that introduces errors up to a maximum QBER of Q. The 
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QBER is dependent on the channel parameters. It results from the errors intrinsic to Alice, Qa, and from the dark 
counts in Bob detectors. In the case of the 2TS protocol, an error occurs, for example, when Alice sends a state \1b) 
and Bob detects |2s). In the case of the 3TS protocol, an error occurs when Alice sends for example a state |/3i) and 
Bob detects a state |3s). The probability to detect in the wrong time-slot comes either from the intrinsic errors of 
the pulse sent by Alice affected by the channel transmission, t]Qa, or from the dark-count probability per time-slot, 
Pd- The total probability detection results either from an incoming photon with probability rj or from the dark-count 
probability corresponding to the two time slots involved in the protocol, 2pd- Therefore, the overall quantum bit error 
rate is given by : 

= rjQA+pd 

In particular, Q increases as n decreases. When the transmission is close to 1, the probability of a dark-count is 
totally negligible and the QBER is equal to the QBER intrinsic to Alice Qa- When the transmission becomes very 
low, the QBER is dominated by the dark-counts and it tends to 1/2. The dependence of the channel transmission 
with distance is given by 77 = r/dr/L where j]d is the quantum efficiency of the detector, and t]l = lCP^o" is the channel 
attenuation where L is the distance in km and a is the attenuation in dB/km. We consider a fiber attenuation a 
= 0.2 dB/km, a superconducting single-photon detector [icj with a dark-count rate of 10 counts/sec, a quantum 
efficiency of 10 % and a pulse duration of T/2 = 10 ns. This leads to a dark-count probability per pulse pd = 10~ 7 . 
For both protocols and for Va equal to 1, 0.95 and 0.9 and Qa = 0.02, we deduce the secure distance from the 
maximum allowed QBER (see figure ([5])). For the original 3TS protocol, we obtain 227, 213 and 182 km. For the 2TS 
protocol or for the C3TS protocol we obtain 253, 250 and 247 km. For a given value of the visibility, the 2TS or the 
C3TS protocols feature a longer secure distance than the original 3TS protocol. This comes clearly form the mutual 
information curves shown on figure |51 Anyhow the difference between both protocols becomes really important for 
low values of the visibility Va- This evaluation shows that the 2TS protocol or the C3TS protocol are better than 
the original 3TS protocol in term of secure distance and that secure distances over 200 km are possible with the 
combination of time-coding protocols and low-noise SSPD. 



VI. PHOTON NUMBER SPLITTING ATTACKS 



Up to now, we have considered single-photon states and the security analysis has been done within the framework 
of this hypothesis. Although the subject of intense experimental research, single-photon states are still difficult to 
produce. Most of the time, QKD devices make use of faint pulses simulating single-photon states when sufficiently 
attenuated. Here, we will analyse the security of the 2TS protocol within this framework. 

The fact that more than one photon can be measured in a pulse makes possible the use of specific attacks on the key 
exchange. One of them, called Photon number splitting attack (PNS) [23| . explicitly exploits the number of photons 
in the pulse. The principle consists for Eve in measuring the number of photons in a given pulse and keeping only 
those with a number of photons greater than 1. Then, Eve keeps one photon and stores it in a quantum memory 
while she lets the remaining part of the pulse be transmitted to Bob. She waits until the end of the reconciliation 
process and the corresponding classical information exchange between Alice and Bob. She then performs the adequate 
measurement, in order to get some knowledge on the key. The limit rate taking into account PNS attacks has been 
given by GLLP (33|. It can be written 

Rfaint > qG^{(l - A)(l - h(Q^/(l - A))) - h(Qv)} (50) 

A is the ratio between the number of multiphoton pulses measured at the output of Alice to the number of pulses 
actually detected by Bob. Therefore, (1 — A) is a lower bound of the proportion of single photon pulses in the signal 
pulses. The first term in the parenthesis represents the mutual information Iab that can be obtained only from single 
photon pulses. The second term is the information available to the eavesdropper that has the same expression as in 
the case of single photon pulses, q is a parameter specific from the protocol, and Q M are the gain and the error 
rate for the signal pulse, that can be evaluated from the channel characterization. In order to calculate each term in 
Eq. (|50l) . we start from the general expression of a two time-slot pulse with average photon number \x. It is described 
by a product of coherent states 

W)Agen = \ai«Jv) I^Vm) 2 (51) 

where |ai| 2 + |a.2 1 2 = 1 and | a.2 1 2 |ai| 2 or |ai| 2 <§; |fl2| 2 , depending on whether a bit or a bit 1 is encoded. Bob 
keeps only the events corresponding to one detection in a time-slot, and no detection in the other one. Therefore, the 
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detection in time-slot 1 is described by the operator Pi = (1 — 1 0) 1 1 (0 1 ) 1 0) 2 2 (0 1 and the detection in time-slot 2 by 
P 2 = (1 — |0)2 2(0|)|0)i i(0|. Taking into account the dark-count probability pd, we obtain the probability to have a 
detection in time-slot 1 (and none in time-slot 2) given by pi = (1 — exp(— \ai\ 2 -q^)) exp(— \a2\ 2 rjfi) + pd- Similarly, 
for time-slot 2, we have pi = (1 — cxp(— 1«2 | 2 77^i)) exp(— |ai| 2 r;/x) + Pd- At the output of the channel, the initial 
coherent state \yfjl) is transformed to \^/r]jT), due to the overall channel transmission. For small values of /x, we can 
deduce the channel gain given by 



and the error rate given by 



From the definition of A, we have 



G> = (1 - cxp(- W )) + 2p d , (52) 



n _ QA(l-exp(-r)n))+p d 



A = i-(/i + 0( M 2 )) (54) 



The expression of /i is thus /1 = 2?yA, showing that the average photon number in the signal pulse has to decrease 
proportionally to the channel transmission if one wants we keep A constant as a function of the distance. We see 
from Eq. (1521) that the rate is proportional to rf as long as r\ is much greater than pd- Taking the same expression for 
?y and the same value for the parameters as in the previous section, we can plot the rate as a function of the distance 
and compare it with the result obtained in the single photon case, as displayed on figure ([7]). Here, for simplicity, we 
have supposed a perfect visibility (Va = 1), and we obtain a limit distance of 90 km. 

One counter-measure to PNS attacks is to introduce decoy states [30l - [32l |. Our goal is to show that decoy states 
can be combined with our protocol in order to reach rates that are close to those obtained with single photon pulses. 
We consider here the case of an asymptotic decoy state method as described in [3l[ which consists for Alice to send 
signal pulses with average photon number /1 and to mix them with a fixed proportion of decoy states that can take all 
possible average photon number values between and \x. It has been proven in [34j that practical methods combining 
one weak decoy state and exploiting the vacuum (vacuum + weak decoy state protocol) can lead to results very close 
to the asymptotic protocol. Therefore, Alice and Bob can deduce precisely the portion of pulses having exactly N 
photons. Thus any attempt to eavesdrop the channel unavoidably modifies the relative part of each N photon states, 
which allows to detect Eve. The GLLP analysis [jOl [33| results in a simple expression for the secure rate given by 



R > q{-G^f(Q^)h(Q^ +Gi[l- HQx)]} (55) 

Gi and Qi are respectively the gain of the channel and the error rate for the one photon pulses, /(Q M ) is the efficiency 
of the reconciliation algorithm. We consider the 2TS protocol with perfect visibility (Va — 1) for simplicity. The 
first term in the parenthesis is the information that can be retrieved by the eavesdropper on the sifted key. The 
second term is the information available to Alice and Bob which can be obtained only from true single photon pulses. 
Considering the states at the output of Alice, given by Eq. (|5"Tj) . and taking into account the overall transmission 77, 
we obtain the expression of the channel gain for the single photon pulses 

G\ = cxp(— (56) 



The error rate in the case of single photon pulses is given by Eq. (1491) . In order to be able to compare it with the 
single photon case, we take q = 1, and we consider that Alice and Bob can perform perfect information extraction, 
which results in /(Q^) = 1. As previously, the overall transmission is given by rj = J]^^. With the same expression 
and parameter values as previously and taking the optimum value fx = 0.5, we can plot the rate as a function of the 
distance and compare it with the result obtained in the single photon case. The curves are displayed on figure (J7]). 
Both of them decrease as 77 with the distance as long as 77 3> pa- The cut-off distance is 250 km for the single photon 
protocol. It is slightly lower for the decoy state protocol (225 km) but comparable. This shows that our protocol 
combined with decoy states can reach secure distances that are comparable to those obtained with single photons. In 
addition, the use of low noise detectors such as SSPD allows to reach unprecedented long secure distances. 



VII. CONCLUSION 



We have given a complete security analysis of time-coding protocols where the bits are encoded in coherent single- 
photon pulses spanning successive time-slots [ill ■ To model the protocol, each time-slot is represented by a basis 
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Figure 7: Decrease of the secure key rate (dB) as a function of the distance (km) for the 2TS protocol with visibility 1. Curve 
(a) is obtained with faint pulses without decoy states. The rate decreases as if until it reaches the cut-off distance. Curve (b) 
is obtained with single photons, curve (c) is obtained combining faint pulses with decoy states. Both curves decrease as r; with 
the distance as long as r\ > pd- When we consider a fiber attenuation of a = 0.2 dB/km, the cut-off distance is 90 km without 
decoy states, 250 km for the single photon protocol and 225 km for the decoy state protocol. 



state in the Hilbert space. We first consider the original protocol Il9f. It is based on three time-slots and can be 
modeled with three orthogonal basis states. We have renamed it Three Time-Slots Protocol (3TS). The bits are 
encoded in single-photon states that are represented by non orthogonal superpositions of the basis states. Therefore, 
it is impossible for Eve to preserve the coherence without introducing errors. 

The mathematical expression describing the protocol can be reformulated. This leads to another protocol requiring 
only two basis states and which has therefore been called Two Time-Slots protocol (2TS). The bits are encoded on two 
orthogonal states corresponding to two successive time-slots. Additional pulses spanning the two adjacent time-slots 
and corresponding to a superposition of the two basis states are added in order to keep Eve from eavesdropping 
the key without introducing errors. A complete analysis of this protocol is given. We calculate the Holevo quantity 
between Alice and Eve as a function of the quantum bit error rate (QBER) for different values of the interferometer 
visibility. We compare it to the Shannon information between Alice and Bob to deduce the advantage of information 
of Alice and Bob over Eve as a function of the QBER. In the case of a perfect visibility of the interferometer, the 
results coincide with those obtained for the BB84 protocol, with a maximum allowed QBER of 11%. 

We then analyse the security of the 3TS protocol. The security analysis is very similar to that of the 2TS protocol. 
This suggests an improved version of the 3TS protocol where additional pulses are sent in addition to the two initial 
pulses. Those pulses are described by a superposition of the two states encoding the key. Measuring the coherence 
between those two states allows Bob to ensure the security of the key. This protocol has been called Completed 
Three Time-Slots protocol (C3TS). The results are identical to those of the 2TS protocol. Then, we have shown that, 
although being less performant, the original 3TS protocol can still allow producing secure keys up to a QBER of the 
order of 5%. 

We then compare the two protocols calculating the maximum secure distance in both cases. We consider a realistic 
implementation involving a standard single mode optical fibre and superconducting single photon detectors. We obtain 
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secure distances with a cut-off of 253 km for the 2TS protocol or the C3TS protocol and 235 km for the original 3TS 
protocol in the case of a perfect visibility (Va = 1)- Such secure distances have recently been demonstrated using 
superconducting single photon detectors and ultra low loss fibres [4lj . 

In order to take into account the case of real experimental implementations involving faint pulses instead of single 
photon pulses, we consider the case of PNS attacks. The protocols are sensitive to those attacks, which imposes a 
quadratic decrease of the rate with the channel attenuation if one wants to preserve the security of the key. Introducing 
decoy states where Alice can modulate the average photon number in the pulses within a known proportion, Alice and 
Bob can rule out those attacks. As a result, the secure rate decreases linearly with the attenuation, which is similar 
to what is obtained with single photon pulses. The secure distance cut-off is 225 km, which is only slightly smaller to 
the cut-off distance obtained with single-photon pulses. As a result, our time-coding protocols combined with decoy 
states are able to give security distances exceeding 200 km. This feature, in addition to their easy implementation, 
makes them good candidates for field implementation of long distance QKD links. 
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